Companies Still Suffering From Poor Credential Hygiene: New Report

Credentials are being mis-handled and it's hurting most companies, according to a new report out today.

A new report, the 2018 Privileged Access Threat Report from Bomgar, contains cause for worry for those who care about IT security since its numbers carry the clear message that, when it comes to keeping up with identities, most companies are getting it wrong.

According to the survey of more than 1,000 IT professionals with ties to system access, half of companies polled say that they either have had a serious breach or expect one within the next six months. Of those giving a positive response to the breach question, roughly two-thirds pin the blame on mis-used credentials.

Blame for this credential abuse falls on two large points: employee mis-use, and mis-use by trusted third parties. Third parties come in for most of the scrutiny, but it's clear that employees are far from off the hook.

As for the third parties, the credential problem seems to point to a larger company culture issue: 73% of those responding say that their companies are too reliant on third parties for critical work, while 72% say that they are simply too trusting of their third party vendors.

Join Dark Reading LIVE for two cybersecurity summits at Interop ITX. Learn from the industry’s most knowledgeable IT security experts. Check out the security track here. Register with Promo Code DR200 and save $200.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.

In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possib...

Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-portal\conf\server.xml) that could potentially be exploited by malicious users to compromise the affected system.

In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request with %2e instead of '.' characters, as demonstrated by an initial /h2hdocumentation//%2e%2e/ substring.